Feed/CVE-2026-52724
CVE-2026-52724MEDIUMCVSS 0.0

kuma-dp connects to control plane without verifying TLS certificate when no CA is configured

Published Jul 16, 2026·Updated Jul 16, 2026

NVD Description

When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verification disabled. The dataplane authentication token is sent over this unverified connection ## Impact An on-path attacker can intercept the dataplane authentication token and impersonate the control plane to the data plane, allowing them to inject a forged bootstrap configuration and take over the proxy ## Affected configurations - Universal mode `kuma-dp` started against an HTTPS control plane without `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT` unset) ## Not affected - Kubernetes installs done through the standard installers (`kumactl install control-plane` or the official Helm chart). In both cases the control plane's mutating admission webhook injects `KUMA_CONTROL_PLANE_CA_CERT` into every sidecar at pod admission, so each `kuma-dp` starts with the CA already configured ## Workarounds Set `--ca-cert-file` (or `KUMA_CONTROL_PLANE_CA_CERT`) on every Universal mode data plane and point it at the control plane's serving CA. Alternatively, terminate the control plane behind a publicly trusted certificate; the patched releases will verify successfully against the operating system trust store with no further configuration ## Resources - Fix: https://github.com/kumahq/kuma/pull/16777

Affected Packages (2)

github.com/kumahq/kumaGO
Fixed in = 1.8.1
github.com/kumahq/kuma/v2GO
Fixed in 2.7.26

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free